All errata/sisyphus/ALT-PU-2021-4847-1
ALT-PU-2021-4847-1

Package update openocd in branch sisyphus

Version0.11.0-alt1.rc1
Published2024-04-05
Max severityCRITICAL
Severity:

Closed issues (1)

CVE-2018-5704
CRITICAL9.6

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

Published: 2018-01-16Modified: 2024-11-21
CVSS 2.0CRITICAL 9.3
CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS 3.xCRITICAL 9.6
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H